priivacy
Executive Overview

Personal-data risk, at a glance.

The headline numbers, the risk posture, and the obligations that matter — the bottom line on personal-data exposure for leadership.

Across 1 scan, this assessment analysed 439,609 files and identified 126,131 containing personally identifiable information (28.7% exposure rate), with 907,185 total PII instances detected. Of these, 48,685 critical and 5,846 high-risk files require immediate attention. Bank Account (BSB + Account) is the most frequently detected PII type (561,443 instances).
Prepared for
ACME INC - SP
Source
SharePoint · 409,757 documents
Issued
14 September 2026
Framework
General Data Protection Regulation
Risk posture
High
Overall exposure rating
54531 critical/high files
drive the rating
Restricted
608,760
Most-sensitive findings
67% of findings
restricted items
Estate exposed
31%
Of documents hold PII
126,131 of 409,757
documents
Critical-risk
48,685
Files at critical risk
5,846 high-risk
also need attention

Risk posture

sensitivity-weighted exposure
88
Exposure index

Elevated exposure

A high share of identifiable records carry restricted-grade PII (TFN, Medicare, passport), concentrated in a small number of documents.

608,760 restricted-grade findings
Sensitivity distribution
Restricted
608,760
Confidential
261,400
Internal
37,025
Public
0

What we found

top types by instance
1
Bank Account (BSB + Account)Restricted
561,443
2
Date of BirthConfidential
231,628
3
Tax File Number (TFN)Restricted
40,713
4
Person NameInternal
36,382
5
Centrelink CRNConfidential
20,571

Compliance impact

General Data Protection Regulation · EU/UK
402,315 scanned · 7,442 partial · 3,803 declined · 23,797 excluded · 240 failed
Security of processingCritical
Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
274,043 findings · 93,288 files
Notification of a personal data breach to the supervisory authorityCritical
Data controllers must notify the supervisory authority within 72 hours of becoming aware of a breach where it poses risk to rights and freedoms.
46,746 findings · 19,759 files
Principles relating to processing of personal dataHigh
Data must be processed lawfully, fairly, transparently; collected for specified purposes; adequate, relevant, limited.
268,010 findings · 91,570 files

Top actions

what to do next
1
Review the 608,760 restricted-grade findings flagged in this assessment.
2
Prioritise the highest-sensitivity data — Bank Account (BSB + Account) and Date of Birth.
3
Apply retention policies to aged data — 44,935 findings sit in documents over 10 years old.